libsoup's implementation of HTTP range requests is vulnerable to a resource consumption attack. A malicious client may request the same range many times in a single HTTP request, causing the server to use large amounts of memory.